A patient at your first location texts to move her Thursday visit. The reply comes from the practice number, lands in a shared inbox, and shows who sent it.
Across town, at the clinic you bought last spring, another patient asks the same thing. That answer comes from a medical assistant's personal iPhone, where it joins years of threads the group has never seen.
Both patients got a fast reply. Only one of those replies exists anywhere you can find it.
We think HIPAA-compliant texting governance for Tebra group practices holds only when the approved channel is faster than a personal phone. Every new location also needs that channel on day one of the deal.
Tebra already gives you tight control over who sees what. Its user settings limit each login to the practices that person can access, in line with HIPAA's minimum necessary rule.
A text sent from a personal phone skips every one of those settings. It has no role, no practice scope, and no log.
For a group that grows by buying practices, this risk stacks up. Each deal adds staff, and each team brings the shortcuts it built over years of doing things its own way. Few of those shortcuts show up in diligence, because nobody on either side thinks to ask about them.
The owner usually carries what turns up later, often without a compliance team to call. That's why patient texting compliance in a growing group can't wait for the first complaint. It needs to be part of how you open, run, and absorb every site.
Shadow texting is patient texting that happens outside any system the group owns. It shows up at almost every location, and it starts for good reasons.
It works, and staff know it. A patient who can't reach the front desk by phone will text the number she has. Often that's the MA who helped her last time.
Compare the paths for one simple ask, like "Can I come at 3 instead of 2?" The portal route means a login the patient forgot, a message that waits in a queue, and a reply she may never see.
The phone route means one call, a hold, and maybe a voicemail. A personal text gets an answer in two minutes.
So staff reach for their own phones during the busy hours. Three patients are waiting to check in, the lines are ringing, and a text is the fastest way to clear one task. Nobody plans it. It becomes the habit because it saves time every single day.
Diligence checklists are long. They cover payer contracts, leases, staff agreements, and the EHR move. Few of them ask, "Which phones do your staff use to text patients?"
That silence is where acquisition-inherited compliance risk hides. A common pattern plays out a few months after closing.
The owner learns that the acquired clinic's most loved MA has texted patients from her own phone since 2019. There are hundreds of threads with names, visit times, refill questions, and photos of rashes.
All of it sits on a device the group has never seen, can't search, and can't wipe. It's now the group's problem to manage.
The phone likely backs up to her personal cloud account too, so the threads live in a second place you don't control. If she quits next year, those records leave with her.
Patients who saved her number will keep texting it, and some will never learn the practice has a main line.
Sooner or later, someone asks for the full record. It might be a patient complaint, a lawyer's subpoena, or an OCR inquiry. Each one wants every communication with a named patient.
Your team can pull Tebra notes and portal messages in an afternoon. Then comes the gap. Staff with PHI on a personal phone would have to hand over the device or send screenshots. You'd have no way to check that the set is complete.
"That happened before we owned them" doesn't help much either. Any text sent after closing came from your workforce, so the exposure keeps growing each week the habit goes on.
HIPAA's Security Rule has an audit controls standard, 45 CFR 164.312(b). It calls for ways to record and review activity in systems that hold electronic PHI. A personal phone offers none of that to the group.
Penalties can be steep. Under HHS's current inflation-adjusted penalty tiers, the top tier carries a yearly cap of $2,134,831 for the same type of violation.
Most owners respond the same way. They add a line to the handbook and announce it at the next staff meeting: no patient texting from personal phones.
Two weeks later, the lines are still busy and patients still text the numbers they have. Staff face a choice between breaking a rule and letting a patient wait. Most pick the patient, and they're not wrong to care about her.
We'd go a step further. A ban without a faster tool pushes texting further out of sight, because staff stop mentioning it. Inherited habits are the hardest to move, since the acquired team built them long before your policy existed.
Signed policy forms don't help much here. An MA can sign the form on Monday and answer a patient from her own phone on Tuesday, and both acts feel reasonable to her.
Curogram gives each location one sanctioned texting channel, tied to the practice number and built to beat the personal phone on speed. When the approved path is also the quick one, staff move to it on their own, at old sites and new ones.
Speed is the whole case for adoption. Staff reply from a shared inbox on a desktop or the mobile app. Saved templates handle the common asks, like directions, parking, forms, and "please arrive 15 minutes early."
Routing keeps the right person on each thread. A billing question goes to billing, and a reschedule goes to the front desk at that site. Nobody has to forward a screenshot.
Automation also takes load off the phones, which removes the reason staff started texting in the first place.
Based on our internal data, practices using automated texting saw inbound calls drop by 24%, and some cut phone volume by up to 50%. Fewer calls means fewer moments where a personal phone looks like the fastest fix.
Tebra already scopes users. Its practice access settings let an admin grant a login only to the practices that person needs. Your texting channel should follow the same logic.
With role-based access, a front desk user at the east clinic sees the east clinic inbox. A biller sees payment threads across the sites she covers. A regional manager sees everything in her region, and nobody sees more than their job needs.
Offboarding changes too. When an MA leaves, you turn off one login, and her patient threads stay with the practice. Compare that with asking a departing employee to delete years of texts from her own phone and trusting that she did.
Every message in the channel is logged with the sender, the time, the location, and the patient. That gives you an audit trail of patient texts across all locations, in one place.
When a request arrives, you search by patient and date range. The export shows the full thread, including who replied and when, so you're not piecing it together from memory. This is the kind of record the audit controls standard has in mind.
Curogram also pulls patient and appointment data from the EHR. Each thread sits against the right patient and visit, which cuts the mix-ups that happen when two patients share a name at different sites.
Any texting vendor that touches PHI is a business associate under HIPAA. Get a signed BAA from your texting vendor before a single patient message goes out. If a vendor won't sign one, that ends the talk. Curogram signs one.
Past the BAA, ask for proof. If a vendor sells itself as a SOC 2 patient messaging platform, request the full Type II report, check the dates it covers, and read the exceptions section. A logo on a sales page tells you very little.
Success here has one number: 100% of patient texts on governed, logged channels. That includes every site, even the one you closed on last month. Getting there is a rollout job, and it's shorter than most owners expect.
This plan is illustrative. Adjust the timing to the size of the site and how many staff text today.
After the rollout, each new deal brings your standard to their site, with the same templates, roles, and export process from week one.
That matters most for groups that close two or three deals a year. A new site manager learns one system, and your compliance lead reviews one log.
Track the 100% goal with two simple checks each month. Ask each site lead whether any staff still text patients from personal phones, and pull a spot sample of five patient histories per site. When both come back clean for three months, the site is done.
Staff keep what they wanted in the first place. Replies are still fast, patients still text a number they know, and the MA still gets to help people quickly. The only change is where the thread lives.
Role-Based Access & Audit Trails is how Curogram keeps texting governed as a Tebra group adds sites. Each user gets a login scoped to their location and their job. Each message is logged with who sent it, when, from which site, and to which patient.
For owners, the daily value is control without a security team. You add a location and set roles, and the new site's running under the same rules as the rest. When someone leaves, you turn off one login and the threads stay with the practice.
For staff, the value is speed. Templates cover the common asks, routing sends each thread to the right person, and the shared inbox means nobody's stuck guarding a single phone. Automated reminders and two-way replies take pressure off the phones, which is the pressure that started shadow texting.
The same channel handles the work that fills a day. Based on our internal data, Covina Arthritic Clinic confirmed an average of more than 1,100 appointments a month through automated texts. One multi-location practice saw 1,240 patients come back from SMS recall messages alone. Every one of those messages sits in the same governed log.
Content rules are built in. Default templates keep PHI out of the text body, and results or balances go through a secure link or encrypted messaging. Curogram signs a BAA, and patient and visit data flows in from the EHR so each thread sits against the right record.
When an audit request comes in, you search by patient and date, then export the full history across every location.
Patients will keep texting, and staff will keep answering from whatever gets the reply out fastest. What an owner controls is which channel is fastest, and whether every site has it on the day you close.
Tebra runs your practice operations, from scheduling to claims. Curogram carries the everyday conversations around them, held to the same standard at every door you own. Together they give each new location a clear setup: Tebra for the chart and the schedule, a governed channel for the texts.
Before your next deal, ask one question about your last one. "Could we produce every patient text from their last quarter?" If the answer takes more than a second, act on that pause.
Start with the acquired sites, since that's where habits are oldest and least visible. Then fold the same rollout into your standard integration list, so the next clinic gets it with payroll and the EHR move.
Schedule a demo with our team. We'll walk you through the access settings and a sample audit export, and our BAA terms are ready for your review.